Establish which identity is being misused
Brand impersonation is the use of a trusted organisation’s or person’s identity to mislead someone. The visible symptom may be a lookalike domain, a cloned website, a social profile, an advertisement or a message. Start with the exact address or account identifier, the claimed identity, the requested action and the people exposed. A similar name alone does not establish fraud; document the actual misleading behaviour.
Separate three possibilities: misuse of your real domain in a forged message, an attacker-controlled domain that resembles yours, and compromise of a genuine account. They require different technical checks and response owners. A fraudulent instruction sent through a real, compromised mailbox can pass email authentication. A lookalike domain may have correctly configured authentication for its own name.
Preserve a small, useful evidence package
Keep original suspicious messages with their full headers and attachments through an agreed evidence-handling process. Record the full URL or profile identifier, observation time and time zone, screenshots with context, relevant message identifiers and the action requested. Retain originals separately from annotated working copies. Record who collected each item, how, and any limitations; avoid circulating confidential customer information to everyone involved.
Specialists can examine relevant public domain records, DNS responses, certificate information and observable page behaviour within an authorised scope. Shared hosting, a certificate or a registration timestamp is a lead, not proof of common ownership or the human operator. Do not enter credentials into the suspicious site, download unknown files or engage the impersonator to “test” the fraud.
A response path with clear decision points
- Identify
Record the claimed identity, exact location and requested action.
- Preserve
Keep original messages, observations and collection context.
- Protect
Verify payment requests and restrict confirmed exposure with the responsible team.
- Escalate
Send relevant evidence to the correct provider; track decisions and recurrence.
Reduce exposure while the investigation continues
Use a verified communication channel to tell the relevant finance, customer support, IT or executive office team what is known. Preserve exact indicators before sharing them as warnings, and make clear which are confirmed and which remain under review. Internal filtering or blocking decisions should consider legitimate business dependencies and be recorded with an owner and review time.
If payment is involved, the authorised finance contact should speak promptly to the bank through a verified channel. Independently verify changes in payment details using a previously established contact route, not a number supplied in the suspicious message. The FBI recommends this kind of independent verification for business email compromise. A technical investigation and a bank recovery request are separate actions; neither establishes that funds can be recovered.
Send the right evidence to the right recipient
Identify the service responsible for the observed abuse: a social platform for a fake profile, a hosting provider for a malicious page, or a registrar for domain-related abuse. A useful report explains what is being impersonated, the exact location, the observed harmful behaviour, the evidence and a contact authorised to represent the affected organisation. Retain submission receipts and case identifiers so later reviewers can reconstruct the response.
ICANN describes a registrar-first reporting route for relevant generic top-level domain abuse, with contractual-compliance escalation in appropriate cases. Country-code domains and content or trademark disputes can follow different processes. A provider assesses the report under its own remit and policies; investigation does not guarantee removal or a fixed takedown time. Legal advisers should guide rights-based claims and any procedural requirements.
Understand what email authentication can and cannot fix
SPF identifies authorised sending infrastructure, DKIM provides a domain-linked message signature, and DMARC evaluates alignment with the domain shown in the From address and publishes handling and reporting policy. Review legitimate senders, forwarding and third-party mailing services before changing enforcement, then monitor delivery and authentication results. A policy change without an inventory of business senders can disrupt legitimate mail.
These controls help protect your domain from unauthorised use. They do not reserve similar-looking domain names, remove social profiles, prove a sender’s business intent or make a compromised genuine mailbox safe. Combine them with account protection, reliable recovery channels, payment verification and an escalation process for external impersonation.
Distinguish the signal from the conclusion
This is an illustrative triage matrix, not a finding about a real organisation.
On a small screen, scroll the table sideways to compare all columns.
| Observed signal | What to establish next | What it does not prove |
|---|---|---|
| Similar domain or shared infrastructure | Exact spelling, recorded behaviour, relevant public records and affected workflow. | Common ownership, criminal intent or the identity of a person. |
| Payment instruction from a known address | Original message, independent authorisation and relevant account activity. | That the request is genuine simply because the email authenticated. |
| Profile using a name and photograph | Stable account identifier, claimed affiliation and misleading conduct. | That every account with the same name is fraudulent. |
Agree an investigation and monitoring scope
For an enterprise, identify brand variants, subsidiaries, executive identities, priority countries, languages and the business processes at risk. For a family office or private client, include authorised representatives and sensitive payment relationships only where relevant and agreed. Define coverage sources, review frequency, alert recipients and escalation thresholds. Monitoring cannot promise visibility into every private group, platform or newly created domain.
Ask for a report that distinguishes confirmed abuse, suspicious leads, false positives and unresolved findings. Each actionable item should include an evidence reference, business relevance, recommended action, responsible owner and next review. Useful measures include time to assess a report, completeness of evidence, verified actions and recurrence; raw alert volume alone says little about protection.
Prepare a useful enquiry for TRUST-IT
Tell us whether the concern involves a domain, profile, email or payment request; when it was first observed; whether activity appears ongoing; and who can authorise the investigation. A short description is enough for the initial public form or AI assistant. Credentials, identity documents, financial records and confidential evidence should be exchanged only through a channel agreed with the team.
TRUST-IT can scope public-source research, digital brand intelligence and related email, cloud or device investigation where authorised. We agree the questions, evidence access, deliverables, reporting recipients and response responsibilities before work begins. If the genuine account may be compromised, use the Microsoft 365 response guide alongside the brand investigation rather than treating every symptom as an external fake.
Further reading
- ICANN — DNS abuse reporting and escalation
- FBI — Business email compromise
- Cloudflare — DMARC, DKIM and SPF
Put the guidance to work
Open-source research, threat intelligence, social media monitoring, and assessment of impersonation and digital exposure.
Threat intelligence & brand protection